
Highlighting Code Block Security & Risk Analysis
wordpress.org/plugins/highlighting-code-blockAdd code block with syntax highlighting using prism.js. (Available for Gutenberg and Classic Editor)
Is Highlighting Code Block Safe to Use in 2026?
Generally Safe
Score 85/100Highlighting Code Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "highlighting-code-block" v2.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. The complete absence of known CVEs and a clean vulnerability history are highly positive indicators. The code does not utilize dangerous functions, all SQL queries are prepared, and there are no file operations or external HTTP requests, which significantly reduces the attack surface. The lack of any taint analysis findings further suggests that user-supplied data is not being improperly handled within the analyzed code paths.
However, the analysis does raise some concerns. The extremely low percentage of properly escaped output (14%) is a significant red flag. This suggests that data displayed to users might be vulnerable to cross-site scripting (XSS) attacks, as untrusted input could be rendered directly in the browser without proper sanitization. Furthermore, the complete absence of capability checks and nonce checks, combined with zero unprotected entry points identified in the attack surface, is peculiar. While it suggests the plugin might not have direct user-facing interfaces that require such checks in its current form, it also means there's no explicit security layer present for any potential future additions or if its intended usage involves interactions not captured by the static analysis. The plugin's strengths lie in its clean history and absence of critical code-level vulnerabilities, but the output escaping deficiency is a notable weakness that needs immediate attention.
Key Concerns
- Low output escaping percentage
- Missing capability checks
- Missing nonce checks
Highlighting Code Block Security Vulnerabilities
Highlighting Code Block Code Analysis
Output Escaping
Highlighting Code Block Attack Surface
WordPress Hooks 13
Maintenance & Trust
Highlighting Code Block Maintenance & Trust
Maintenance Signals
Community Trust
Highlighting Code Block Alternatives
Melonpan Block – Code
melonpan-block-code
Block to display code, with highlighted syntax, which can be copied to the clipboard.
HTML Editor Syntax Highlighter
html-editor-syntax-highlighter
Add syntax highlighting to WordPress code editors using CodeMirror.js
Useful Blocks
useful-blocks
It is a plugin that collects very convenient blocks.
Code Block Pro – Beautiful Syntax Highlighting
code-block-pro
Code highlighting powered by the VS Code engine. Performance focused. No bloat.
CodeMirror Blocks
wp-codemirror-block
CodeMirror Blocks is useful for tutorial site where display formatted (highlighted) code block. With support of 100+ Language/Mode and 56 Themes.
Highlighting Code Block Developer Profile
6 plugins · 135K total installs
How We Detect Highlighting Code Block
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/highlighting-code-block/build/js/code-block/index.js/wp-content/plugins/highlighting-code-block/build/css/hcb.css/wp-content/plugins/highlighting-code-block/assets/js/prism.js/wp-content/plugins/highlighting-code-block/build/js/hcb_script.js/wp-content/plugins/highlighting-code-block/build/css/hcb-admin.css/wp-content/plugins/highlighting-code-block/build/css/editor-style.css/wp-content/plugins/highlighting-code-block/assets/js/hcb.js/wp-content/plugins/highlighting-code-block/build/js/code-block/index.js/wp-content/plugins/highlighting-code-block/assets/js/prism.js/wp-content/plugins/highlighting-code-block/build/js/hcb_script.js/wp-content/plugins/highlighting-code-block/assets/js/hcb.jshighlighting-code-block/build/js/code-block/index.js?ver=highlighting-code-block/build/css/hcb.css?ver=highlighting-code-block/assets/js/prism.js?ver=highlighting-code-block/build/js/hcb_script.js?ver=highlighting-code-block/build/css/hcb-admin.css?ver=highlighting-code-block/build/css/editor-style.css?ver=highlighting-code-block/assets/js/hcb.js?ver=HTML / DOM Fingerprints
wp-block-loos-hcb-code-blockdata-show-copy-btnhcbLangshcbVars